CRITICAL 9.0 npm

Next.js: Unauthenticated Remote Code Execution on windows-hosted servers

GHSA-p293-qw3h-jr36 · CVE-2026-75604

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

A vulnerability in applications using Pages and App router without Cache Component can lead to remote code execution when the server is hosted on machines using a Windows filesystem.

Workaround

There is no known workaround for affected windows-hosted applications. You should upgrade immediately if your server is hosted on Windows.

Ready to move

Start Securing

Free, no credit card | First findings in minutes